Acknowledgements

The BBC wishes to thank the following Security Researchers who have participated in our Vulnerability Disclosure Programme

2025

Researcher                                                     Vulnerability                                    Date
Hepin RadadiyaInjectionDec 2025
Gurudatt ChoudharyInjectionNov 2025
Ghifari AzharInjectionNov 2025
x24_HAVOC (NEPAL)InjectionNov 2025
Musa Hamonangan LubisInjectionNov 2025
Whiterose.svgBroken Access ControlOct 2025
Gurudatt ChoudharyBroken Access ControlOct 2025
Surya ArigelaSecurity MisconfigurationOct 2025
MD KIMIA SADATVulnerable and Outdated ComponentsOct 2025
Adhithya S DBroken Access ControlOct 2025
x24_HAVOCInjectionSept 2025
Sakil Hasan SaikatBroken Access ControlSept 2025
Hepin RadadiyaBroken Access ControlSept 2025
Mihir PankhawalaBroken Access ControlAugust 2025
Rohit Yadav (rohsec)Server-Side Request Forgery (SSRF)July 2025
Sushil Phuyal (1337mickey)InjectionJuly 2025
Miguel LlamazaresInjectionJune 2025
Zer0 WaysBroken Access ControlMay 2025
Pranav R WattamwarInjectionMay 2025
Prabin JoshiInjectionMay 2025
Kanhaiya SharmaInjectionMay 2025
Rajan KshedalInjectionMay 2025
Rajan KshedalInjectionApril 2025
Rajan KshedalInjectionApril 2025
Wren/Blue WoodBroken Access ControlApril 2025
x24_HAVOC ( NEPAL )InjectionApril 2025
Karthikeyan CInsecure DesignApril 2025
Parth NarulaInsecure DesignApril 2025
Ajay Anand CTGInsecure DesignApril 2025
X24_CAIRO (NEPAL)InjectionApril 2025
Varad P MeneInsecure DesignApril 2025
Varad P MeneInsecure DesignApril 2025
SURAJ BHATTARAI (Nepal)Insecure DesignApril 2025
cyberritzzzInsecure DesignMarch 2025
cyberritzzzInsecure DesignMarch 2025
Gurudatt ChoudharyInsecure DesignMarch 2025
SURAJ BHATTARAI (Nepal)Insecure DesignMarch 2025
Vishal KumarSecurity MisconfigurationMarch 2025
Sushil Phuyal (1337mickey)Injection March 2025
Sushil Phuyal (1337mickey)InjectionMarch 2025
Gurudatt ChoudharyInjectionMarch 2025
Varad P MeneInsecure DesignMarch 2025
Gurudatt ChoudharyVulnerable and Outdated ComponentsMarch 2025
Noor Mohammad GagguturiVulnerable and Outdated ComponentsFebruary 2025
Atharv Rokade (Lordofheaven)Insecure DesignFebruary 2025
Siddesh NingappaInsecure DesignFebruary 2025
Raman R MohurleInsecure DesignFebruary 2025
MPGODMATCH...!Identification and Authentication Failure February 2025
defalt47Insecure DesignFebruary 2025
SARATHY DInsecure DesignFebruary 2025
Gurudatt ChoudharyBroken Access ControlFebruary 2025
Varad P MeneData Integrity FailureFebruary 2025
Varad P MeneData Integrity FailureJanuary 2025
Billy SheppardInjectionJanuary 2025
Mohammed Nafeed (H4cker Nafeed)Broken Access ControlJanuary 2025

2024

ResearcherVulnerability Date
NavreetInsecure DesignDec 2024
Raman R MohurleInsecure DesignDec 2024
Gurudatt ChoudharyVulnerable and Outdated ComponentsDec 2024
Arif DudekulaVulnerable and Outdated ComponentsDec 2024
RenganathanInsecure DesignDec 2024
Bikram Kharal(@themarkib)Security MisconfigurationNov 2024
Oum V ZarkarInsecure DesignNov 2024
Kasani ShivaTejaInjectionNov 2024
Richard Hyunho Im (@richeeta)Broken Access ControlNov 2024
Harsh N NavgaleInjectionNov 2024
Raman R MohurleInjectionNov 2024
Althaf AshrafInsecure DesignOct  2024
Late - Khadananda PhuyalInjectionOct 2024
ராஜ்குமார் சண்முகம் (Rajkumar Shanmugam)Broken Access ControlOct 2024
Rajkumar ShanmugamVulnerable and Outdated ComponentsSept 2024
Aashutosh Devkota ( Nepal )Insecure DesignAugust 2024
Bruno GarciaInjectionAugust 2024
Chinmaya RanaBroken Access ControlAugust 2024
Guilherme GonçalvesInsecure DesignAugust 2024
Subhankar PaulSecurity MisconfigurationJuly 2024
Aadesh JainVulnerable and Outdated ComponentsJuly 2024
Kartik GargVulnerable and Outdated ComponentsJuly 2024
Karthikeyan V (Cappricio Securities)Security MisconfigurationJuly 2024
Claudio RizzoInjectionJuly 2024
Hritom BhattacharyaInsecure DesignJuly 2024
Vaibhav JainInjectionJune 2024
Omri InbarInsecure DesignJune 2024
Ariel RachamimInsecure DesignJune 2024
Vedant RoyInsecure Design June 2024
Abhith DamodaranInjectionMay 2024
Vikas Anand (kingcoolvikas)Security MisconfigurationMay 2024
Rohit Yadav (rohsec)Broken Access ControlMay 2024
HarishSecurity MisconfigurationMay 2024
Yash kulkarniSecurity MisconfigurationMay 2024
Harsh N NavgaleSensitive Information DisclosureMay 2024
Sanjith Roshan U Sensitive Information DisclosureMay 2024
Vikas AnandSecurity MisconfigurationApril 2024
Shivam DhingraSecurity MisconfigurationApril 2024
Raman R MohurleSecurity MisconfigurationApril 2024
Pruthu RautSensitive Information DisclosureApril 2024
@karthithehackerSecurity MisconfigurationApril 2024
Nikhil RaneInjectionApril 2024
Kartik GargInformation DisclosureApril 2024
Abid AhmadSecurity MisconfigurationMarch 2024
Chinmaya RanaInsecure DesignMarch 2024
Anže Jenšterle (CraftByte)Broken Access ControlMarch 2024
Anurag MewarInformation Disclosure February 2024
Vikas AnandSecurity MisconfigurationFebruary 2024
NITYA NAND JHA(Shunux)InjectionFebruary 2024
Vinit LakraBroken AuthenticationFebruary 2024
Soham LadInjectionJanuary 2024
Raman R MohurleSecurity MisconfigurationJanuary 2024

 

2023

Researcher                              Vulnerability                                  Date                         
Vishak VSecurity misconfiguration Dec 2023
Rajdip Dey SarkarInjectionDec 2023
Brijesh (Redhet)Insecure DesignDec 2023
Aditya SinghInjectionDec 2023
Noor Mohammad GagguturiInjectionDec 2023
Usman Idris ChouguleInjectionDec 2023
Mohamed Akees (Sri Lanka)InjectionDec 2023
K.Rajesh SagarSecurity MisconfigurationDec 2023
Miguel Segovia GilData IntegrityDec 2023
Vibhor SharmaInsecure DesignNov 2023
Yash kulkarniBroken Access ControlNov 2023
Yash kulkarniBroken Access ControlNov 2023
Yash kulkarniInsecure DesignNov 2023
Yash KulkarniBroken Access ControlNov 2023
Abhith DamodaranInjectionNov 2023
Mayur Pandya (GDSCPU, Cybertalk)Insecure DesignNov 2023
Yash KulkarniBroken Access ControlNov 2023
Mayur Pandya (Parul University, Cybertalk)InjectionOct 2023
Mayur Pandya (Parul University, Cybertalk)Data IntegrityOct 2023
Mayur Pandya (Parul University, Cybertalk)Insecure DesignOct 2023
Yash KulkarniBroken Access ControlOct 2023
white_rose_0101Broken Access ControlOct 2023
Milan JainInjectionOct 2023
Yash KulkarniInsecure DesignOct 2023
Vinit LakraSecurity MisconfigurationOct 2023
Shivam SharmaInjectionOct 2023
Durvesh KolheOutdated ComponentsSept 2023
Brijesh (Redhet)InjectionSept 2023
Martin van WingerdenSecurity MisconfigurationSept 2023
Parag BagulOutdated ComponentsSept 2023
Nilabh RajpootOutdated ComponentsAug 2023
Mohamed IbrahimInjectionAug 2023
Banavath AravindInsecure DesignJuly 2023
Shivam SharmaInjectionJuly 2023
Banavath AravindInjectionJuly 2023
Ankit KapoorSecurity MisconfigurationJune 2023
Nasser Hassen AltowairqiInjectionJune 2023
Ramansh SharmaBroken Access ControlJune 2023
Parag BagulOutdated ComponentsJune 2023
Ramansh SharmaInsecure DesignJune 2023
Roshan PoudelInsecure DesignMay 2023
Joshua ProvosteInjectionMay 2023
Josef HassanOutdated ComponentsMay 2023
Ahmed HassanOutdated ComponentsMay 2023
M7arm4nInjectionMay 2023
Vedant ShindeInjectionApril 2023
Jose Carlos Exposito BuenoSecurity MisconfigurationApril 2023
Ayush AggarwalInjectionApril 2023
Mohd.Den ComptonInsecure DesignMarch 2023
Abir Khan HridoyInjectionMarch 2023
Pedro CardosoInjectionMarch 2023
Prial IslamInsecure DesignMarch 2023
Siddharth PasalapudiBroken Access ControlMarch 2023
Momen Eldawakhly (Cyber Guy)Broken Access ControlMarch 2023
Karthik U.J.InjectionMarch 2023
Abdalla AliData IntegrityMarch 2023
Łukasz TlałkaInjectionMarch 2023
Billy SheppardInjectionMarch 2023
Akshay RaviInjectionFeb 2023
Pratham RajgorServer-Side Request ForgeryFeb 2023
Vijay MahajanServer-Side Request ForgeryJan 2023
Ayush AggarwalInjectionJan 2023
Vedavyasan SInjectionJan 2023
Pratham RajgorInjectionJan 2023
Banavath AravindInjectionJan 2023
Billy Sheppard & Petter OlsenData IntegrityJan 2023
Vishal VishwakarmaInjectionJan 2023
Benavath AravindBroken Access ControlJan 2023
Sebin ThomasInjectionJan 2023

 

2022

ResearcherVulnerabilityDate
Narayanan MInsecure DesignDec 2022
Ramansh SharmaInjectionDec 2022
Banavath AravindInjectionNov 2022
Milan Jain (scriptkiddie)InjectionNov 2022
Banavath AravindData IntegrityNov 2022
Abdalla AliInjectionOct 2022
Ayush AggarwalInjectionSept 2022
Ahmad Henry MansourInjectionAug 2022
JeyabalajiInsecure DesignJuly 2022
Toby DavenportInjectionJuly 2022
Nitesh SinghData IntegrityJuly 2022
Ayush AggarwalInjectionJuly 2022
James BuckleyBroken Access ControlJuly 2022
Felipe Gabriel RenziData IntegrityJun 2022
Dzmitry SmaliakInjectionMay 2022
Jordan GloverData IntegrityApr 2022
Alana WittenBroken Access ControlMar 2022
Kevin Yehezkiel GurningInjectionMar 2022
Toby DavenportInsecure DesignFeb 2022
Toby DavenportInformation DisclosureJan 2022
Toby Davenport Information DisclosureJan 2022
Vikas Srivastava                       Security MisconfigurationJan 2022                   

 

2021

ResearcherVulnerability

Date

Ayush AggarwalInjectionDec 2021
Vikas SrivastavaRemote Code ExecutionDec 2021
Crispin JeyaPrakash.A (B1ackHood)Remote Code ExecutionDec 2021
Ishan VyasRemote Code ExecutionNov 2021
Rohit YadavRemote Code ExecutionNov 2021
Karthik UJRemote Code ExecutionNov 2021
Ai Ho (@j3ssiejjj)Remote Code ExecutionNov 2021
Mohd.Danish AbidData IntegrityNov 2021
Abhijith AData IntegrityNov 2021
SuprasServer-Side Request ForgeryOct 2021
Rohit YadavSecurity MisconfigurationOct 2021
Pranav KSecurity MisconfigurationOct 2021
Roshan PoudélInsecure DesignOct 2021
Nessim Jerbi (Tunisia)Insecure DesignOct 2021
Ayush AggarwalSecurity MisconfigurationSept 2021
Momen Ali Eldawakhly (Cyber Guy)Data IntegrityAug 2021
Momen Ali Eldawakhly (Cyber Guy)Broken Access ControlAug 2021
Momen Ali Eldawakhly (Cyber Guy)Broken Access ControlAug 2021
Nourhan Ali Dief (Cyber Girl)Data IntegrityAug 2021
Shubham GargInjectionAug 2021
Momen Ali Eldawakhly (Cyber Guy)InjectionAug 2021
Momen Ali Eldawakhly (Cyber Guy)Vulnerable ComponentsAug 2021
Nourhan Ali Ibrahim DiefData IntegrityAug 2021
Gourab SadhukhanData IntegrityAug 2021
Abhijith A Broken Access ControlAug 2021
Anirudh Srinivas BalajiData IntegrityAug 2021
Mohit KhemchandaniData IntegrityAug 2021
Raajesh.GVulnerable ComponentsAug 2021
Michele RomanoInjectionAug 2021
Shubham GargSecurity MisconfigurationAug 2021
Jefferson Gonzales (Gonz)InjectionAug 2021
Kabeer SaxenaVulnerable ComponentsAug 2021
Prathamesh Surekha Prakash PawarInjectionAug 2021
Nayanjyoti RoySecurity MisconfigurationJuly 2021
Abhijeet SarkarInsecure DesignJuly 2021
Roshan PoudélInsecure DesignJuly 2021
Rishabh ShrivastavaData IntegrityJuly 2021
Roshan PoudélInsecure DesignJuly 2021
Kiran Ghimire (From Nepal)Data IntegrityJuly 2021
Chandan RaiInsecure DesignJuly 2021
Mayank MukhiOutdated ComponentsJuly 2021
Luca ConsolatiInjectionJune 2021
Chirag Ketan PrajapatiInjectionJune 2021
Ishan VyasInjectionJune 2021
Sheikh RishadBroken Access ControlJune 2021
Avdi ZumerayBroken Access ControlJune 2021
Mike RalphsonData IntegrityJune 2021
Pratik KhalaneBroken Access ControlJune 2021
Anirudh MakkarBroken Access ControlJune 2021
Mohamed Abdellatif JaberInjectionMay 2021
Bartłomiej BergierInjectionMay 2021
Diego Bernal AdelantadoSecurity MisconfigurationMay 2021
Enes SaltikVulnerable ComponentsMay 2021
Divya SinghInjectionApril 2021
Faiyaz AhmadBroken Access ControlApril 2021
Roshan PoudélVulnerable ComponentsMarch 2021
Ai HoData IntegrityMarch 2021
Satrya Wira YudhaInsecure DesignMarch 2021
Ai HoSecurity MisconfigurationMarch 2021
Ahmed ElmalkyData IntegrityMarch 2021
Bijay SilwalInjectionMarch 2021
Eslam Sayed(eslamXxX)InjectionMarch 2021
Abhinav SharmaSecurity MisconfigurationMarch 2021
Ganesh BagariaInjectionMarch 2021
Colin BarrSecurity MisconfigurationMarch 2021
Buğra EskiciSecurity MisconfigurationFebruary 2021
Bartłomiej BergierInjectionFebruary 2021
Harsh ParekhData IntegrityFebruary 2021
Enes SaltikVulnerable ComponentsJanuary 2021
Bartłomiej BergierInjectionJanuary 2021
0xblackbirdData IntegrityJanuary 2021
Nitesh SinghInjectionJanuary 2021
Erdoğan Yağız ŞahinSecurity MisconfigurationJanuary 2021

2020

ResearcherVulnerability

Date

Osama KhanInjectionDecember 2020
Alfred NirmalData IntegrityDecember 2020
Taha BıyıklıInjectionDecember 2020
Tayfun AKYILDIZInjectionDecember 2020
René de SainInjectionNovember 2020
Tom SmithVulnerable ComponentsNovember 2020
Alexandar ThangavelSecurity MisconfigurationNovember 2020 
Sourajeet MajumderInsecure DesignNovember 2020
Netanel RubinData IntegrityNovember 2020
Shaun BuddingInjectionNovember 2020
Pratik DabhiVulnerable ComponentsNovember 2020
Brijesh PandyaInjectionNovember 2020
Pentest PeopleInjectionNovember 2020
Shaikh Yaser ArafatVulnerable ComponentsNovember 2020
Sanem SudheendraVulnerable ComponentsNovember 2020
Gaurav MishraInjectionNovember 2020
Pritam MukherjeeInjectionNovember 2020
Parshwa PareshKumar BhavsarInjectionOctober 2020
Azizul HakimInsecure DesignOctober 2020
Kasper KarlssonInjectionOctober 2020
Benjamin Barnes (Magna)InjectionOctober 2020
Roberto Urbanus InjectionOctober 2020
Pritam DashInjectionOctober 2020
Lucio SáInjectionOctober 2020
Suraj DisojaInjectionOctober 2020
Bharat (Mr.NOOB)Multiple VulnerabilitiesOctober 2020
Nathan JonesData IntegrityOctober 2020
Ed WilliamsInsecure DesignOctober 2020
Junting ZhuInjectionSeptember 2020
Gal NagliData IntegritySeptember 2020
Jeya Seelan SData IntegritySeptember 2020
George OmnetServer side request forgerySeptember 2020
Devang KareliaInjectionSeptember 2020
Ashley KingInjectionSeptember 2020
Sumit GroverInjectionSeptember 2020
Daniel LidénInjectionSeptember 2020
Alessandro Christo RumampukInjectionSeptember 2020
Vikas Srivastava, IndiaInsecure DesignAugust 2020
d3vpoo1Server-Side Request ForgeryAugust 2020
Keshav MalikInsecure DesignAugust 2020
Abhinav PData IntegrityAugust 2020
Gamer7112InjectionAugust 2020
Shivang TrivediData IntegrityAugust 2020
Tommaso De PontiInsecure DesignJuly 2020
Gourab SadhukhanBroken Access ControlJuly 2020
Prakhar MittalBroken Access ControlJuly 2020
Florian KunushevciData IntegrityJuly 2020
Parag DaveSecurity MisconfigurationJuly 2020
Hassan CypherData IntegrityJuly 2020
Pankaj Kumar Thakur (Nepal)InjectionJuly 2020
Prasoon GuptaSecurity MisconfigurationJune 2020
Utkarsh AgrawalData IntegrityJune 2020
Joseph Buta Data IntegrityJune 2020
Sumit GroverSecurity MisconfigurationJune 2020
Pethuraj MData IntegrityMay 2020
Subhamoy GuhaInsecure DesignMay 2020
Akash BasnetInsecure DesignMay 2020
Ahmad HalabiVulnerable ComponentsMay 2020
Vivek SinghSecurity MisconfigurationApril 2020
Anurag MuleyInsecure DesignApril 2020
Diego Bernal AdelantadoInjectionApril 2020
Lütfü Mert CeylanInjectionApril 2020
Syed Muhammad AsimInjectionFebruary 2020
Govind palakkalSecurity MisconfigurationJanuary 2020
Abhaychandra Chede- Tarun MahourData IntegrityJanuary 2020
Noman ShaikhInjectionJanuary 2020
Mike RalphsonData IntegrityJanuary 2020
Conny DahlgrenInjectionJanuary 2020
Mohamad Mohsin ShekhData IntegrityJanuary 2020
Raphael KargerInjectionJanuary 2020
Robbie WigginsVulnerable ComponentsJanuary 2020
Nathan HrncirikInjectionJanuary 2020
Shivam PandeyInsecure DesignJanuary 2020

2019

ResearcherVulnerability

Date

Onkar SonawaneData IntegrityDecember 2019
DarkprincesriInjectionDecember 2019
Chippa Vijay KumarInjectionDecember 2019
Alessandro Christo RumampukInjectionNovember 2019
Sourajeet MajumderInsecure DesignOctober 2019
Safak AslanInjectionOctober 2019
Diego Bernal AdelantadoInjectionSeptember 2019
Akhil GeorgeSecurity MisconfigurationAugust 2019
Amey TakekarInjectionJuly 2019
Parker DaudtInjectionMay 2019
Tinu TomyInjectionMay 2019
Wasim ShaikhInjectionMay 2019
Acelakshit vermaInjectionMay 2019
Angel TsvetkovInjectionApril 2019
Pethuraj MInjectionApril 2019 
Jayateertha GInjectionApril 2019
Dhrudeep PatelInjectionMarch 2019
Wai Yan AungInjectionMarch 2019
Vineet KumarSecurity MisconfigurationMarch 2019
Anjali PatilInjectionMarch 2019
Ashish KunwarData IntegrityMarch 2019
EdOverflowInjectionMarch 2019
Nathan MahdaviBroken Access ControlFebruary 2019
B. FranklinSecurity MisconfigurationFebruary 2019
Nicholas DineInjectionFebruary 2019
Anurag JainBroken Access ControlJanuary 2019
Damian SchwyrzInjectionJanuary 2019

2018 

ResearcherVulnerabilityDate
Dan KelleyInjectionDecember 2018
Varun ThoratInjectionDecember 2018
Eric HeadInjectionNovember 2018
CyberanteaterInjectionNovember 2018
Avinash JainInjectionNovember 2018
Pranshu Tiwari InjectionNovember 2018
Aldo MorenoInjectionOctober 2018
Diego MoicanoInjectionOctober 2018
Trung NguyenSecurity MisconfigurationOctober 2018
Hrishikesh PanseInjectionOctober 2018 
Sébastien KaulSecurity MisconfigurationOctober 2018 
Richard StrnadSecurity MisconfigurationSeptember 2018
Puneet Kumar MauryaSecurity MisconfigurationSeptember 2018
JubaBaghdadInjectionSeptember 2018
Dhiraj MishraInsecure DesignSeptember 2018 
Efkan GökbasData IntegritySeptember 2018 
Kunal BahlInsecure DesignSeptember 2018 
Saubhagya SrivastavaInsecure DesignSeptember 2018 
Kenan GUMUSInjectionSeptember 2018 
B.DhiyaneshwaranData IntegritySeptember 2018 
Alfie NjeruBroken Access ControlAugust 2018
Michael SkeltonSecurity MisconfigurationAugust 2018
Robbie WigginsSecurity MisconfigurationAugust 2018
Thijs BaartInjectionAugust 2018
Sean RoesnerInjectionAugust 2018
Sam GilderInsecure DesignAugust 2018
Nicolas FrancoisInjectionAugust 2018
Zeeshan KhalidInjectionAugust 2018
Joby JohnData IntegrityAugust 2018
Christoph KisfeldInjectionAugust 2018
Pedro CardosoInjectionAugust 2018 
Naveen.vData IntegrityAugust 2018 
Deepak R PandeyBroken Access ControlAugust 2018
Ashutosh BarotData IntegrityJuly 2018

2017

ResearcherVulnerability

Date

Shwetabh SumanInjectionFebruary 2017

Information for reporters

Please note that we are currently backfilling this page with reporter information. If you have reported a vulnerability which has been accepted and your details are not here already but you would like them to be, please contact [email protected] and include the reference number you were provided with along with the name/handle and a link to a social media account if you wish that to appear here.

The BBC relies on consent to publish the personal information of researchers online. We will include a link to the researchers’ social media profiles, but only if the researcher asks us to do so. The researcher can withdraw their consent at any time by contacting [email protected]. For further information about how the BBC processes your personal information including your rights under data protection law, please see the BBC’s privacy policy.

Info: Website links

Please note that we only link to security researcher social media profiles. Our trust model does not enable us to link to other websites. Currently LinkedIn, Twitter(X), Instagram, Facebook and HackerOne profile links are accepted. Other social media sites will be reviewed and considered at point of request. Mastodon is a de-centralised system and therefore we will reference handles (please ensure you include the @server element), but will not include hyperlinks as we cannot guarantee the safety of the profile being linked to.

Rebuild Page

The page will automatically reload. You may need to reload again if the build takes longer than expected.

Useful links

Demo mode

Hides preview environment warning banner on preview pages.

Theme toggler

Select a theme and theme mode and click "Load theme" to load in your theme combination.

Theme:
Theme Mode: